peter bassill · operator
$ cve CVE-2015-5123 JSON

CVE-2015-5123 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 18.8% (pctl 97)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-04.

Description

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS18.83% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2022-05-04
Public exploitnone known
Published2015-07-14
Last modified2026-06-17

CISA KEV

NameAdobe Flash Player Use-After-Free Vulnerability
Added2022-04-13
Due2022-05-04
Vendor / productAdobe / Flash Player
Ransomware usenone reported

Affected (12)

VendorProduct
adobeflash player
adobeflash player desktop runtime
applemacos
linuxlinux kernel
microsoftwindows
opensuseevergreen
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server eus
redhatenterprise linux workstation
suselinux enterprise desktop
suselinux enterprise workstation extension

References

→ the Explorer  ·  watch your stack  ·  NVD